CVE-2025-52896

HIGH EPSS 15.1%
Published Jun 30, 20251y ago · Modified Jun 17, 20262w ago
8.6 CVSS 4.0
High
Find Similar
Published Jun 30, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.94.2 and 15.57.0. There are no workarounds for this issue other than upgrading.

CVSS Details

Base Score
8.6
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
15.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-79 Cross-site Scripting Injection

Affected Products 2

VendorProductVersionRange
frappefrappe* <14.94.2
frappefrappe*≥15.0.0  –  <15.57.0

References 4

  • github.com https://github.com/frappe/frappe/commit/152fd09de5bca16b8d299d715a1f5df6fca3866f
    Patch
  • github.com https://github.com/frappe/frappe/commit/f11c53d4df745b58bd1c1c08e1634a2f5a55322a
    Patch
  • github.com https://github.com/frappe/frappe/pull/31483
    Issue Tracking
  • github.com https://github.com/frappe/frappe/security/advisories/GHSA-hv29-66qg-2v6p
    Vendor Advisory

Remediation

  • github.com https://github.com/frappe/frappe/commit/152fd09de5bca16b8d299d715a1f5df6fca3866f
    Patch
  • github.com https://github.com/frappe/frappe/commit/f11c53d4df745b58bd1c1c08e1634a2f5a55322a
    Patch